Follow-up r90482: escape some more wikitext
authorMatěj Grabovský <mgrabovsky@users.mediawiki.org>
Wed, 22 Jun 2011 14:59:05 +0000 (14:59 +0000)
committerMatěj Grabovský <mgrabovsky@users.mediawiki.org>
Wed, 22 Jun 2011 14:59:05 +0000 (14:59 +0000)
includes/FileDeleteForm.php
includes/specials/SpecialUserlogin.php

index 854005b..54c19f0 100644 (file)
@@ -253,7 +253,7 @@ class FileDeleteForm {
                        return wfMsgExt(
                                "{$message}-old", # To ensure grep will find them: 'filedelete-intro-old', 'filedelete-nofile-old', 'filedelete-success-old'
                                'parse',
-                               $this->title->getText(),
+                               wfEscapeWikiText( $this->title->getText() ),
                                $wgLang->date( $this->getTimestamp(), true ),
                                $wgLang->time( $this->getTimestamp(), true ),
                                wfExpandUrl( $this->file->getArchiveUrl( $this->oldimage ) ) );
@@ -261,7 +261,7 @@ class FileDeleteForm {
                        return wfMsgExt(
                                $message,
                                'parse',
-                               $this->title->getText()
+                               wfEscapeWikiText( $this->title->getText() )
                        );
                }
        }
index 12f4f28..e16e00f 100644 (file)
@@ -831,7 +831,7 @@ class LoginForm extends SpecialPage {
 
                $wgOut->setPageTitle( wfMsg( 'loginsuccesstitle' ) );
                if( $msgname ){
-                       $wgOut->addWikiMsg( $msgname, $wgUser->getName() );
+                       $wgOut->addWikiMsg( $msgname, wfEscapeWikiText( $wgUser->getName() ) );
                }
                
                $wgOut->addHTML( $injected_html );